• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Question When gmail is the mail provider, should our maillog show auth attemps?

jorge ceballos

Regular Pleskian
Server operating system version
Centos 7.9.2009
Plesk version and microupdate number
Plesk Obsidian Versión 18.0.52 Actualización 3
Hi,
Have a couple of clients whose email service is Gmail hosted.
We act as their main DNS and their NS - w/glue - are pointed to us; mail service is completely deactivated on this side for these domains.
Both reported yesterday they were missing mail from certain providers such as hotmail and yahoo.
Monitored maillog and came to my attention that yesterday maillog showed unusual activity trying to auth multiple email accounts belonging to these domains.
Is this behavior ok ? or something changed at Google ?
TIA
 
I am not quite understanding the question but as long as the MX records is pointing to google's service (which could be found here) and has the SPF setup correctly, your server shouldn't be doing anything other then sending the service that's trying to send the email know where to route the emails. If you have anything in the maillog trying to auth email accounts belonging to those domains means either someone is trying to do something bad or someone did set their web site form or whatever setup correctly.
 
Thanks, that's whats I thought, just wanted to be sure.
Seems like a DNS server's caché somewhere is stuck with an old récord.

Regards
 
It is also common that others try to break into mailboxes by brute-force attacks. It can help to have Fail2Ban in place and the Postfix, Dovecot and Recidive rules active.
 
Back
Top